Related Stories

  • Information security in China: A license to print money
    With 200 million internet users in China, and a predicted annual growth rate of 17% for the information security market until 2013, why would security vendors want to go anywhere else? William Knight investigates
  • Companies leap to new web and mobile technologies leaving security behind
    Companies are embracing new web and mobile technologies such as cloud computing, virtualisation, social networking and mobile communication at a faster rate than their information security strategies are updated.
  • What’s in store for 2010?
    The Noughties are behind us now, but memories of a decade of data breaches will continue to haunt the infosec professional. If only there was a way of knowing what the threat landscape would look like in the months to come. Well you’re in luck as Davey Winder has dusted off the crystal ball and spoken to a broad church of infosec professionals to get some informed predictions for 2010
  • Which? publishes PC security new year resolutions
    It's a new year, so time for those resolutions and, says Which? Magazine, it's also time for a few security resolutions for your computer.
  • Spamming the socially active - spam diversifies to Twitter, IM, SMS, etc
    Once poison found only in email accounts, spam is now polluting every form of electronic communication from IM to SMS and from blogs to tweets. But how well is it doing outside its natural domain? William Knight takes a look at non-email spam

News

Microsoft, security and a digital Britain

30 September 2009

Ed Gibson, CSO at Microsoft UK explored risks posed by criminals to the digital economy and security at the Security for a Digital Britain conference in Nottingham on 24 September.

Gibson raised a number of security issues with a digital Britain, and pointed out potential security weak spots that could be, and are, exploited by cybercriminals.

The Microsoft CSO said that despite the UK having the “strictest spam legislation in the world”, for example, there are still “huge amounts of spam” – the anti-spam legislation only covers private spam, not business spam. Malicious spam can of course lead victims to malware websites and/or lead to other security threats.

Windows Vista – security overboard

Looking at Microsoft’s own products, Gibson said many have complained of Windows Vista being too slow, but said the reason why, is because Microsoft built a lot of security into Vista - “but we went a bit overboard”, he admitted.

Users are constantly asked whether they really want to do this and that, and in the end, users end up clicking ‘yes’ to everything, because most users cannot distinguish for example a safe ActiveX from an unsafe one, Gibson pointed out.

The Microsoft CSO warned people to think twice before accepting various plug-ins and installs online for security reasons.

He also warned against using the new Google Chrome without reading the terms and conditions carefully. He claimed once users accept Google’s terms and conditions for Chrome, it is “no longer your computer, but Google’s”.

Not only free browsers could pose a security issue, Gibson said. The free anti-virus and anti-malware software offered by more and more banks in the UK to make online banking safer, could cause serious problems on users’ computers if they already have a running anti-virus software. The two anti-virus software tools could start attacking each other and render the end user less secure than before.

Another security threat, Gibson told the audience, could be cloud computing. Do you know that your data is safe? And do you know where it is being stored?

Social networking – a security threat in more than one way

It is not only malware spread through social networking services that could pose a security risk, Gibson said, using a hypothetical example of soldiers on Facebook in Afghanistan.

Even if a soldier does not have a profile himself, one of his colleagues may blog about him/her exposing his/her whereabouts.

Furthermore, information found on social networking sites, could be used by cybercirminals for social engineering.

If a soldier posts ‘I’m going home on the 1 October’, a cybercriminal can use this information and send the soldier’s grandma an email pretending to be the soldier saying ‘I’m stuck in X. Please send me some money so I can get home’.

All responsible for security

In his concluding remarks, Gibson told the audience that we are all responsible for digital security by knowing what software we have on our computer, keep security software updated, and to think before clicking ‘yes’ on those security warnings.

 

This article is featured in:
Application Security Compliance and Policy Data Loss Identity and Access Management Internet and Network Security Malware and Hardware Security Public Sector

 

Comment on this article

You must be registered and logged in to leave a comment about this article.